VYPR

SEVD-2024-072-02

by Schneider Electric

CVEs (4)

  • CVE-2024-2051CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.01

    CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the login form.

  • CVE-2024-2050HigMar 18, 2024
    risk 0.53cvss 8.2epss 0.00

    CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code within the context of the product.

  • CVE-2024-2229HigMar 18, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution when a malicious project file is loaded into the application by a valid user.

  • CVE-2024-2052HigMar 18, 2024
    risk 0.49cvss 7.5epss 0.01

    CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated files and logs exfiltration and download of files when an attacker modifies the URL to download to a different location.